LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ayass BioScience Listed by alphv Ransomware Group

HIGH severityUnverified claimHow we verify

Ayass BioScience Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 6, 2023
Ayass BioScience Listed by alphv Ransomware Group

Reported September 6, 2023.

HIGH
Severity
September 6, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Ayass BioScience Listed by alphv Ransomware Group (reported September 6, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 06, 2023, Ayass BioScience was listed by the alphv ransomware group, which claimed to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the incident is limited to that listing and the description of internal files taken. For an organisation that provides genetic testing, any confirmed exposure of internal material carries weight because such firms routinely handle sensitive health-related information.

What is established so far is the claim itself and the reported date; method, full scope, and confirmation of the data’s contents have not been publicly detailed beyond the group’s assertion.

What happened

According to the available record, Ayass BioScience appeared on an alphv leak-site listing dated September 06, 2023. The group stated that internal files had been exfiltrated in a ransomware attack. No figure for affected individuals has been released, and the precise timing of the intrusion, the entry vector, and whether systems were encrypted or solely data was allegedly stolen are undisclosed. The listing constitutes the group’s claim; independent confirmation of the full extent of the incident has not been supplied in the public facts.

In short, the known core is a ransomware-related claim of internal-file theft against a genetic-testing company, reported in early September 2023, with scale and technical particulars still unconfirmed.

Inside alphv

Alphv, also widely known in public reporting as BlackCat, is a ransomware operation that emerged in late 2021 and has operated under a ransomware-as-a-service model. Affiliates typically gain access to victim networks, exfiltrate data, and deploy encryption, then pressure organisations by threatening to publish stolen material on a dedicated leak site if a ransom is not paid. The group has been linked to numerous high-profile incidents across healthcare, manufacturing, and professional services, often using double-extortion tactics that combine encryption with data theft.

Public analyses have described alphv’s use of custom ransomware written in Rust, flexible negotiation portals, and a willingness to target organisations holding regulated or sensitive data. In this case, the group’s listing of Ayass BioScience is presented as its own claim that internal files were taken; no additional statements attributed specifically to this victim beyond that listing appear in the given facts. Law-enforcement actions and infrastructure disruptions have affected the brand over time, yet listings under the alphv name continued to surface in 2023.

About Ayass BioScience

Ayass BioScience, LLC describes itself as a provider of genetic testing that supplies genomic information intended to help individuals make informed decisions about health-care management and prevention. Organisations in this sector typically collect and process biological samples, generate test results, maintain laboratory and patient records, and store associated administrative and clinical data. Because genetic information is inherently personal and often linked to family health histories, firms of this type are regarded as holding high-sensitivity material even when they operate at modest scale.

A breach claim against such an entity matters because the data ecosystem around genetic testing can include identifiers, clinical notes, billing details, and the genomic results themselves. Even when only “internal files” are named, the potential intersection with health and genetic records elevates the stakes for patients, referring clinicians, and the laboratory’s own operations and reputation.

What was likely exposed

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, record counts, or specific data categories has been disclosed. Organisations offering genetic testing commonly hold patient demographics, test orders and results, laboratory information-system data, insurance or billing records, employee information, and operational documents. It is therefore reasonable to expect that internal files could encompass some mixture of those categories, yet the exact contents remain unconfirmed.

Readers should treat any assumption about precise data elements as provisional until official notification or a verified inventory is released. The public record does not name Social Security numbers, full genomic sequences, or any other specific field as having been exposed.

The real-world impact

For individuals whose information may have been among the internal files, the primary risks include unwanted contact, targeted phishing that references legitimate test or appointment details, and longer-term concerns about the misuse of health-related data. Genetic information, if present, cannot be changed like a password; its exposure can carry lasting privacy implications for the person tested and, in some cases, biological relatives. Financial or identity-related harm is also possible if administrative or billing records were included, though that inclusion is not confirmed.

For Ayass BioScience the consequences can include regulatory scrutiny under health-privacy rules, notification costs, potential civil claims, disruption of laboratory and customer operations, and reputational damage that affects patient and partner trust. Because the number of people affected is unknown, the organisation and any regulators would need to complete a proper scoping exercise before the full human and operational impact can be measured. Until then, caution and monitoring remain the practical response.

What to do if you're exposed

If you have been a patient, customer, or employee of Ayass BioScience, watch for official breach notifications from the company or regulators; those notices, when issued, will describe what was involved and any recommended steps. In the meantime, be alert to unexpected emails, calls, or messages that reference genetic testing or personal health details, and treat unsolicited requests for further information or payment with skepticism. Consider placing fraud alerts or credit freezes if you later learn that financial identifiers were involved, and keep records of any suspicious activity.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That check does not confirm involvement in this specific incident, but it can help you decide whether broader credential changes or monitoring services are warranted while waiting for clearer official details.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAyass BioScience security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Ayass BioScience’s full breach history →

More recent breaches

Viking Therapeutics Listed by alphv Ransomware GroupDecember 19, 2023Viking Therapeutics reported to the SEC following a breach Listed by alphv Ransomware GroupDecember 18, 2023LeClair Group Listed by alphv Ransomware GroupDecember 13, 2023Henry Schein Inc - Henry's " LOST SHINE " Listed by alphv Ransomware GroupDecember 5, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Ayass BioScience Listed by alphv Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by alphv — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram